Previewing a response in Devtools ignored CSP headers,...
Moderate severity
Unreviewed
Published
May 27, 2025
to the GitHub Advisory Database
•
Updated Jun 11, 2025
Description
Published by the National Vulnerability Database
May 27, 2025
Published to the GitHub Advisory Database
May 27, 2025
Last updated
Jun 11, 2025
Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerability affects Firefox < 139.
References